CVE-2020-6779
high-risk
Published 2021-01-26
Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as well as a high availability impact on the database itself. In addition, an attacker may execute arbitrary commands on the underlying operating system.
Do I need to act?
~
9.9% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
10
CVSS 10.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (2)
Fsm-2500 Firmware
Fsm-5000 Firmware
Affected Vendors
References (2)
51
/ 100
high-risk
Severity
33/34 · Critical
Exploitability
11/34 · Low
Exposure
7/34 · Low